Patentable/Patents/US-20260220279-A1
US-20260220279-A1

User Presence Detect to Enable a Remote Support Agent and Secure User Content

PublishedJuly 30, 2026
Assigneenot available in USPTO data we have
Technical Abstract

An information handling system includes a memory to store code and a processor to execute code. The code grants a remote access request to a support service, and blurs a portion of an image provided to the support service based upon a predetermined list of content in response to granting the remote access request. The portion includes at least one item of content from the list.

Patent Claims

Legal claims defining the scope of protection, as filed with the USPTO.

1

a memory device configured to store code; and grant a remote access request to a support service; and blur a portion of an image provided to the support service based upon a predetermined list of content in response to granting the remote access request, wherein the portion includes at least one item of content from the list. a processor configured to execute code to: . An information handling system, comprising:

2

claim 1 . The information handling system of, wherein blurring the portion of the image is in response to determining that a user is proximate to the information handling system.

3

claim 2 User Presence Detect (UPD) configured to determine that the user is proximate to the information handling system. . The information handling system of, further comprising:

4

claim 3 . The information handling system of, wherein blurring the portion of the image is in further response to determining that the user is an authenticated user of the information handling system.

5

claim 4 an authentication framework configured to authenticate the user. . The information handling system of, further comprising:

6

claim 1 . The information handling system of, wherein blurring the portion of the image is in response to determining that a user is not proximate to the information handling system.

7

claim 6 . The information handling system of, wherein, prior to blurring the portion of the image, the code is further to determine that the user is proximate to the information handling system.

8

claim 7 . The information handling system of, wherein, after determining that the user is not proximate to the information handling system, the code is further to maintain a session with the support service.

9

claim 1 out-of-band management hardware configured to initiate a support session in response to granting the remote access request. . The information handling system of, further comprising:

10

granting, by a processor of an information handling system, a remote access request to a support service; and blurring a portion of an image provided to the support service based upon a predetermined list of content in response to granting the remote access request, wherein the portion includes at least one item of content from the list. . A method, comprising:

11

claim 10 . The method of, wherein blurring the portion of the image is in response to determining that a user is proximate to the information handling system.

12

claim 11 determining, by User Presence Detect (UPD) hardware of the information handling system, that the user is proximate to the information handling system. . The method of, further comprising:

13

claim 12 . The method of, wherein blurring the portion of the image is in further response to determining that the user is an authenticated user of the information handling system.

14

claim 13 authenticating, by an authentication framework of the information handling system, the user. . The method offurther comprising:

15

claim 10 . The method of, wherein blurring the portion of the image is in response to determining that a user is not proximate to the information handling system.

16

claim 15 determining that the user is proximate to the information handling system. . The method of, wherein, prior to blurring the portion of the image, the method further comprises:

17

claim 16 maintaining a session with the support service. . The method of, wherein, after determining that the user is not proximate to the information handling system, the method further comprises:

18

claim 10 initiating, by out-of-band management hardware of the information handling system, a support session in response to granting the remote access request. . The information handling system of, further comprising:

19

a memory device configured to store code; and grant a remote access request to a support service; blur a portion of an image provided to the support service based upon a predetermined list of content in response to granting the remote access request, wherein the portion includes at least one item of content from the list, and wherein blurring the portion of the image is in response to determining that a user is proximate to the information handling system; a processor configured to execute code to: User Presence Detect (UPD) configured to determine that the user is proximate to the information handling system; and out-of-band management hardware configured to initiate a support session in response to granting the remote access request. . An information handling system, comprising:

20

claim 19 . The information handling system of, wherein blurring the portion of the image is in further response to determining that the user is an authenticated user of the information handling system.

Detailed Description

Complete technical specification and implementation details from the patent document.

This disclosure relates to information handling systems, and more particularly relates to the use of user presence detect features to enable a remote support agent and to secure user content in an information handling system.

As the value and use of information continues to increase, individuals and businesses seek additional ways to process and store information. One option is an information handling system. An information handling system generally processes, compiles, stores, and/or communicates information or data for business, personal, or other purposes. Because technology and information handling needs and requirements may vary between different applications, information handling systems may also vary regarding what information is handled, how the information is handled, how much information is processed, stored, or communicated, and how quickly and efficiently the information may be processed, stored, or communicated. The variations in information handling systems allow for information handling systems to be general or configured for a specific user or specific use such as financial transaction processing, reservations, enterprise data storage, or global communications. In addition, information handling systems may include a variety of hardware and software resources that may be configured to process, store, and communicate information and may include one or more computer systems, data storage systems, and networking systems.

An information handling system may include a memory to store code and a processor to execute code. The code may grant a remote access request to a support service, and blur a portion of an image provided to the support service based upon a predetermined list of content in response to granting the remote access request. The portion includes at least one item of content from the list.

The use of the same reference symbols in different drawings indicates similar or identical items.

The following description in combination with the Figures is provided to assist in understanding the teachings disclosed herein. The following discussion will focus on specific implementations and embodiments of the teachings. This focus is provided to assist in describing the teachings, and should not be interpreted as a limitation on the scope or applicability of the teachings. However, other teachings can certainly be used in this application. The teachings can also be used in other applications, and with several different types of architectures, such as distributed computing architectures, client/server architectures, or middleware server architectures and associated resources.

1 FIG. 100 110 120 130 140 110 100 110 110 100 illustrates an information handling systemincluding a User Presence Detect (UPD) framework, a user authentication framework, a remote access agent, and a content manager. UPD frameworkrepresents hardware and firmware instantiated on information handling systemto detect various environmental inputs that operate to infer the presence of a user in the proximity of the information handling system. For example, UPD frameworkmay include various sensors such as an ambient light sensor, a microphone, a motion sensor, a camera/video device, or the like. UPD frameworkoperates to receive inputs from the various sensors and to determine whether or not a user is present in the proximity of information handling system.

120 100 110 120 120 120 120 User authentication frameworkrepresents a security framework, typically embodied in software or firmware instantiated on information handling system. In this regard, when a user is detected by UPD framework, user authentication frameworkoperates to provide an identity of the user if the particular user is registered within the user authentication framework. In a particular case, when a particular user logs into an operating system for the first time, user authentication frameworkmay operate to prompt the user through various authentication processes and to set up authentication procedures to uniquely identify the user and to indelibly link that user with the particular log-in environment. For example, user authentication frameworkmay set up a username/password authentication, a personal identification number (PIN) authentication, a facial or fingerprint identification authentication, or the like. An example of user authentication frameworkmay include a Windows Hello framework or other third-party authentication frameworks, as needed or desired.

100 190 192 190 100 190 192 100 100 130 100 Information handling systemis illustrated as being connected to an information technology (IT) support servicethat includes a remote access application. IT support servicerepresents a call-in and on-line support service whereby a user of information handling systemcan obtain IT support for issues encountered by the user when using the information handling system. In a typical interaction, the user places a phone call or on-line service request, and a support technician of IT support servicesis provided to talk or text the user through various troubleshooting procedures to identify the problem, and to fix the problem. In this regard, it is common for the IT support technician to invoke remote access applicationto gain first-hand access to information handling system. The IT support technician may send an access request to information handling system. When the access request is granted, remote access agentis invoked which grants user-level access to the resources of information handling systemto the IT support technician.

190 100 100 190 100 Such transactions may be conducted by authorized IT support technicians. That is, IT support servicesmay be a contracted entity or an in-house IT team, and the interactions between the IT support technician and information handling systemare trusted transactions. On the other hand, malicious actors are known to utilize bogus IT support services to attempt to gain access to the resources of information handling system, and thereby to access the user data of unwitting users. As such, it may be desirable to monitor and manage the access granted to IT support services, and to limit the IT support technician's ability to view sensitive data on information handling system.

190 110 120 100 In another case, even when IT support servicesare trusted, a long support session may be difficult because UPD frameworkand user authentication frameworktypically operate to shut down information handling systemwhen no user presence is detected, or a different user is detected as being proximate to the information handling system. Thus, if the user needs a break or needs to attend a meeting, the operating system may shut down in the middle of a support session, leaving the user without a fix to the problem and having to restart a support session upon their return.

140 100 100 140 100 140 100 140 Content managerrepresents a management framework, typically embodied in software or firmware instantiated on information handling systemto manage the interactions between the IT support technician and information handling systemand the sensitive user data displayed thereon. In one aspect, content manageroperates to provide for the blurring of sensitive content stored on information handling systemor displayed on a display device of the information handling system. In a particular case, content managerprovides the user of information handling systemwith selectable options for content viewing, and the selected content is presumptively blurred for the remote support session. For example, the user may select particular content items to blur, such as office productivity files, or may select particular classes of content items to blur. The user may further select particular file folders or sub-folders to be blurred. In another case, content manageroperates based on rules-based or list-based instructions to blur content for the remote session. For example, content or folders displaying a project code name can be selected for blurring. In yet another case, an artificial intelligence/machine learning (AI/ML) model may be utilized to select which content is to be blurred and which content may be viewed in the remote support session.

140 140 100 100 140 100 100 140 110 120 In another aspect, content manageroperates to handle the behavior of the remote support session in the face of the varying UPD and authentication environment. In a particular case, content manageroperates to allow unblurred views into the resources and content on information handling systemwhen an authenticated user is proximate to the information handling system. Then, when the authenticated user leaves the proximity of information handling systemcontent manageroperates to blur the selected content. In this way, an authenticated user's presence is required for the IT support technician to have unfettered access to the resources and content of information handling system. Then, when the user authentication is broken (i.e., when an unautheticated user moves into the place of the authenticated user) or the authenticated user leaves the proximity of information handling system, content manageralternatively provides a warning to the IT support technician that the remote support session is soon to be terminated, or overrides the functionality of UPD frameworkand user authentication frameworkto permit the OS to remain awake while the remote support session is in progress.

190 100 100 150 150 100 100 150 150 100 140 As illustrated and described heretofore, IT support serviceoperates with In-Band functionality of information handling system, that is, based upon a processing environment established on a processor of the information handling system (e.g. a BIOS/OS environment). In another case, information handling systemincludes an optional Out-Of-Band (OOB) management framework. OOB management frameworkrepresents hardware and firmware instantiated on information handling systemto implement an OOB management environment. In this regard, the functions and features of information handling systemmay be instantiated via OOB management framework. However, because OOB management frameworkoperates OOB from the processing environment established on information handling system, a remote support session instantiated via the OOB management framework does not presumptively end when the OS goes to sleep. Thus, in this case, content manageroperates to permit the remote support session to continue when the UPD or user authentication is lost.

2 FIG. 200 200 200 200 200 200 200 illustrates a generalized embodiment of an information handling systemsimilar to information handling system. For purpose of this disclosure an information handling system can include any instrumentality or aggregate of instrumentalities operable to compute, classify, process, transmit, receive, retrieve, originate, switch, store, display, manifest, detect, record, reproduce, handle, or utilize any form of information, intelligence, or data for business, scientific, control, entertainment, or other purposes. For example, information handling systemcan be a personal computer, a laptop computer, a smart phone, a tablet device or other consumer electronic device, a network server, a network storage device, a switch router or other network communication device, or any other suitable device and may vary in size, shape, performance, functionality, and price. Further, information handling systemcan include processing resources for executing machine-executable code, such as a central processing unit (CPU), a programmable logic array (PLA), an embedded device such as a System-on-a-Chip (SoC), or other control logic hardware. Information handling systemcan also include one or more computer-readable medium for storing machine-executable code, such as software or data. Additional components of information handling systemcan include one or more storage devices that can store machine-executable code, one or more communications ports for communicating with external devices, and various input and output (I/O) devices, such as a keyboard, a mouse, and a video display. Information handling systemcan also include one or more buses operable to transmit information between the various hardware components.

200 200 202 204 210 220 225 230 240 250 254 256 260 262 270 274 276 280 290 295 202 204 210 220 230 240 250 254 256 260 262 270 274 276 280 200 200 Information handling systemcan include devices or modules that embody one or more of the devices or modules described below, and operates to perform one or more of the methods described below. Information handling systemincludes a processorsand, an input/output (I/O) interface, memoriesand, a graphics interface, a basic input and output system/universal extensible firmware interface (BIOS/UEFI) module, a disk controller, a hard disk drive (HDD), an optical disk drive (ODD), a disk emulatorconnected to an external solid state drive (SSD), an I/O bridge, one or more add-on resources, a trusted platform module (TPM), a network interface, a management device, and a power supply. Processorsand, I/O interface, memory, graphics interface, BIOS/UEFI module, disk controller, HDD, ODD, disk emulator, SSD, I/O bridge, add-on resources, TPM, and network interfaceoperate together to provide a host environment of information handling systemthat operates to provide the data processing functionality of the information handling system. The host environment operates to execute machine-executable code, including platform BIOS/UEFI code, device firmware, operating system code, applications, programs, and the like, to perform the data processing tasks associated with information handling system.

202 210 206 204 208 220 202 222 225 204 227 230 210 232 236 234 200 202 204 220 230 In the host environment, processoris connected to I/O interfacevia processor interface, and processoris connected to the I/O interface via processor interface. Memoryis connected to processorvia a memory interface. Memoryis connected to processorvia a memory interface. Graphics interfaceis connected to I/O interfacevia a graphics interface, and provides a video display outputto a video display. In a particular embodiment, information handling systemincludes separate memories that are dedicated to each of processorsandvia separate memory interfaces. An example of memoriesandinclude random access memory (RAM) such as static RAM (SRAM), dynamic RAM (DRAM), non-volatile RAM (NV-RAM), or the like, read only memory (ROM), another type of memory, or a combination thereof.

240 250 270 210 212 212 210 240 200 240 200 2 BIOS/UEFI module, disk controller, and I/O bridgeare connected to I/O interfacevia an I/O channel. An example of I/O channelincludes a Peripheral Component Interconnect (PCI) interface, a PCI-Extended (PCI-X) interface, a high-speed PCI-Express (PCIe) interface, another industry standard or proprietary communication interface, or a combination thereof. I/O interfacecan also include one or more other I/O interfaces, including an Industry Standard Architecture (ISA) interface, a Small Computer Serial Interface (SCSI) interface, an Inter-Integrated Circuit (IC) interface, a System Packet Interface (SPI), a Universal Serial Bus (USB), another interface, or a combination thereof. BIOS/UEFI moduleincludes BIOS/UEFI code operable to detect resources within information handling system, to provide drivers for the resources, initialize the resources, and access the resources. BIOS/UEFI moduleincludes code that operates to detect resources within information handling system, to provide drivers for the resources, to initialize the resources, and to access the resources.

250 252 254 256 260 252 260 264 200 262 262 264 200 Disk controllerincludes a disk interfacethat connects the disk controller to HDD, to ODD, and to disk emulator. An example of disk interfaceincludes an Integrated Drive Electronics (IDE) interface, an Advanced Technology Attachment (ATA) such as a parallel ATA (PATA) interface or a serial ATA (SATA) interface, a SCSI interface, a USB interface, a proprietary interface, or a combination thereof. Disk emulatorpermits SSDto be connected to information handling systemvia an external interface. An example of external interfaceincludes a USB interface, an IEEE 1394 (Firewire) interface, a proprietary interface, or a combination thereof. Alternatively, solid-state drivecan be disposed within information handling system.

270 272 274 276 280 272 212 270 212 272 272 274 274 200 I/O bridgeincludes a peripheral interfacethat connects the I/O bridge to add-on resource, to TPM, and to network interface. Peripheral interfacecan be the same type of interface as I/O channel, or can be a different type of interface. As such, I/O bridgeextends the capacity of I/O channelwhere peripheral interfaceand the I/O channel are of the same type, and the I/O bridge translates information from a format suitable to the I/O channel to a format suitable to the peripheral channelwhere they are of a different type. Add-on resourcecan include a data storage system, an additional graphics interface, a network interface card (NIC), a sound/video processing card, another add-on resource, or a combination thereof. Add-on resourcecan be on a main circuit board, on separate circuit board or add-in card disposed within information handling system, a device that is external to the information handling system, or a combination thereof.

280 200 210 280 282 284 200 282 284 272 280 282 284 282 284 Network interfacerepresents a NIC disposed within information handling system, on a main circuit board of the information handling system, integrated onto another component such as I/O interface, in another suitable location, or a combination thereof. Network interface deviceincludes network channelsandthat provide interfaces to devices that are external to information handling system. In a particular embodiment, network channelsandare of a different type than peripheral channeland network interfacetranslates information from a format suitable to the peripheral channel to a format suitable to external devices. An example of network channelsandincludes InfiniBand channels, Fibre Channel channels, Gigabit Ethernet channels, proprietary channel architectures, or a combination thereof. Network channelsandcan be connected to external network resources (not illustrated). The network resource can include another information handling system, a data storage system, another network, a grid management system, another suitable resource, or a combination thereof.

290 200 290 200 290 200 200 290 200 290 290 Management devicerepresents one or more processing devices, such as a dedicated baseboard management controller (BMC) System-on-a-Chip (SoC) device, one or more associated memory devices, one or more network interface devices, a complex programmable logic device (CPLD), and the like, that operate together to provide the management environment for information handling system. In particular, management deviceis connected to various components of the host environment via various internal communication interfaces, such as a Low Pin Count (LPC) interface, an Inter-Integrated-Circuit (I2C) interface, a PCIe interface, or the like, to provide an out-of-band (OOB) mechanism to retrieve information related to the operation of the host environment, to provide BIOS/UEFI or system firmware updates, to manage non-processing components of information handling system, such as system cooling fans and power supplies. Management devicecan include a network connection to an external management system, and the management device can communicate with the management system to report status information for information handling system, to receive BIOS/UEFI or system firmware updates, or to perform other task for managing and controlling the operation of information handling system. Management devicecan operate off of a separate power plane from the components of the host environment so that the management device receives power to manage information handling systemwhere the information handling system is otherwise shut down. An example of management deviceinclude a commercially available BMC product or other device that operates in accordance with an Intelligent Platform Management Initiative (IPMI) specification, a Web Services Management (WSMan) interface, a Redfish Application Programming Interface (API), another Distributed Management Task Force (DMTF), or other management standard, and can include an Integrated Dell Remote Access Controller (iDRAC), an Embedded Controller (EC), or the like. Management devicemay further include associated memory devices, logic devices, security devices, or the like, as needed or desired.

Although only a few exemplary embodiments have been described in detail herein, those skilled in the art will readily appreciate that many modifications are possible in the exemplary embodiments without materially departing from the novel teachings and advantages of the embodiments of the present disclosure. Accordingly, all such modifications are intended to be included within the scope of the embodiments of the present disclosure as defined in the following claims. In the claims, means-plus-function clauses are intended to cover the structures described herein as performing the recited function and not only structural equivalents, but also equivalent structures.

The above-disclosed subject matter is to be considered illustrative, and not restrictive, and the appended claims are intended to cover any and all such modifications, enhancements, and other embodiments that fall within the scope of the present invention. Thus, to the maximum extent allowed by law, the scope of the present invention is to be determined by the broadest permissible interpretation of the following claims and their equivalents, and shall not be restricted or limited by the foregoing detailed description.

Classification Codes (CPC)

Cooperative Patent Classification codes for this invention. Click any code to explore related patents in that topic.

Patent Metadata

Filing Date

January 24, 2025

Publication Date

July 30, 2026

Inventors

Yung-Sheng Lin
Shun-Tang Hsu
Daniel L. Hamlin

Want to explore more patents?

Browse 5M+ US patents with plain-English claim translations and AI-generated analysis.

Citation & reuse

Analysis on this page is generated by Patentable — an AI-powered patent intelligence platform. AI-generated summaries, explanations, and analysis may be reused with attribution and a visible link back to the canonical URL below. Patent abstracts and claims are USPTO public domain.

Cite as: Patentable. “USER PRESENCE DETECT TO ENABLE A REMOTE SUPPORT AGENT AND SECURE USER CONTENT” (US-20260220279-A1). https://patentable.app/patents/US-20260220279-A1

© 2026 Patentable. All rights reserved.

Patentable is a research and drafting-assistant tool, not a law firm, and does not provide legal advice. Documents we generate are drafts for review by a licensed patent attorney.

USER PRESENCE DETECT TO ENABLE A REMOTE SUPPORT AGENT AND SECURE USER CONTENT — Yung-Sheng Lin | Patentable